{"id":48675,"date":"2022-04-07T17:53:06","date_gmt":"2022-04-07T09:53:06","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=48675"},"modified":"2022-04-07T17:53:08","modified_gmt":"2022-04-07T09:53:08","slug":"phls-board-level-executives-assume-theyll-never-be-attacked-despite-rising-ransomware-incidents-sophos","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/04\/07\/phls-board-level-executives-assume-theyll-never-be-attacked-despite-rising-ransomware-incidents-sophos\/","title":{"rendered":"Phl\u2019s board level executives assume they\u2019ll never be attacked despite rising ransomware incidents &#8211; Sophos"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos, a global player in next-generation cybersecurity, announced the findings of the third edition of its survey report, <a href=\"http:\/\/sophos-future-of-cybersecurity-apj-2022-wp.pdf\"><em>The Future of Cybersecurity in Asia Pacific and Japan<\/em><\/a>, in collaboration with Tech Research Asia (TRA). The study reveals a lack of boardroom awareness of cybersecurity, and a broad assumption from executives that their company will never get attacked, despite rising ransomware incidences, impact and cost.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cybersecurity education is an issue, and it starts at the top<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite cybersecurity expenditure and self-assessed maturity increasing in Asia Pacific and Japan (APJ) organizations over the past 12 months, only 47 % of Philippines companies surveyed believe their board truly understands cybersecurity.\u00a0 In addition, the top frustration expressed by Philippine cybersecurity professionals is that cybersecurity is frequently relegated in priority.\u00a0\u00a0\u00a0\u00a0<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-style-large is-layout-flow wp-block-quote-is-layout-flow\"><p>Eighty-nine per cent of respondents from the Philippines also believe cybersecurity vendors do not provide them with the information they need to help educate executives, and 95 % of Philippine companies agree their biggest security challenge in the next 24 months will be the awareness and education of employees and leadership.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The top two attack vectors of concern for APJ organizations are directly addressable by ongoing education and awareness campaigns: phishing or whaling attacks, and weak or compromised employee credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWith ransomware attacks continuing to become more complex, organizations need a genuine, actionable cybersecurity education program. The current reactionary tendencies we\u2019re seeing have created an \u2018attack, change, attack, change \u2026\u2019 cycle regarding cybersecurity strategies, which is putting cybersecurity teams constantly on the backfoot. Shifting priorities to become more proactive must start at the top and requires direction from executives, including investments in awareness and education across entire organizations,\u201d Aaron Bugal, global solutions engineer, APJ, at Sophos.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The skills shortage continues to wreak havoc<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The skills shortage continues to be a key focus area in organizations across the region. Sixty-two per cent of Philippines firms surveyed expect to have some problems with recruiting cybersecurity employees over the coming 24 months; 31 % expect to face a major challenge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With recruiting continuing to pose issues, companies have identified the priority areas they feel skills and capabilities need to be increased for internal security specialists. These include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Cloud security policies and architecture<\/li><li>\u2018Train the trainer\u2019 employee and executive cybersecurity training skills<\/li><li>Software vulnerability testing<\/li><li>Staying up to date with the latest threats<\/li><li>Policy compliance and reporting<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cybersecurity professionals\u2019 top frustrations<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The survey also highlights that cybersecurity professionals face a variety of challenges and frustrations in their roles, most of which are related to awareness, perception, messaging, and education. The top three frustrations across the Philippines are:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Cybersecurity is frequently relegated in priority<\/li><li>Executives assume cybersecurity is easy and cybersecurity professionals over-exaggerate threats and issues<\/li><li>Executives assume their company will never get attacked<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Additional frustrations experienced by cybersecurity professionals across the region include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Executives thinking there is nothing that can be done to stop attacks<\/li><li>Inability to keep up with pace of security threats<\/li><li>Not enough investment and time into training general staff<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cCybersecurity professionals continue to face many frustrations in their roles this year, with many feeling their warnings and messages fall on deaf ears. Apart from lacking skilled security specialists, many of the other frustrations are directly addressable through education and awareness programs, starting at the executive and board level. The challenge for cybersecurity professionals faced with low levels of security understanding among company boards is that many are unlikely to invest in the necessary programs to alleviate these frustrations,\u201d said Bugal.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-style-large is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cThe issue isn\u2019t technology, it\u2019s education. Increasing spend on cybersecurity won\u2019t help unless organizations understand from the top down the true nature and critical threat that cyberattacks constitute to their organizational capabilities, their customers and their own existence.\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity education must become a focus. The following is a five-step approach to help bring organisations up to speed on cybersecurity education:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Boards need help to understand it\u2019s impossible to protect everything, and learn to prioritize the most critical information, data and systems to protect.<\/li><li>Education courses on basic principles, genuine likelihood of an attack, attack vectors, threat actors, and other terminology should be available to all staff.<\/li><li>Once basics are clearly defined, organizations need to develop strategy and integrate with digital transformation programs.<\/li><li>The focus then becomes more operational in nature: applying legislation, breach response protocol, ransom payment policy, gap assessments, and future roles and obligations.<\/li><li>Businesses need to clearly understand compliance, the regulatory environment under which the business operates, what\u2019s legally required when breached and what are the appropriate controls around data security and management.<\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Only 47 % of Philippines companies surveyed believe their board truly understands cybersecurity.\u00a0 In addition, the top frustration expressed by Philippine cybersecurity professionals is that cybersecurity is frequently relegated in priority.\u00a0\u00a0\u00a0\u00a0<\/p>\n","protected":false},"author":6,"featured_media":47548,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,18],"tags":[6498,6151,286,54,2103,206],"class_list":["post-48675","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-white-papers","tag-good-tech","tag-high-tech","tag-it-security","tag-security","tag-security-breach","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/48675","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=48675"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/48675\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/47548"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=48675"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=48675"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=48675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}